Tayvion Payton

DevOps Engineer

Dallas, Texas, United States8 yrs 11 mos experience

Key Highlights

  • Expert in enterprise threat detection and cloud security strategy.
  • Proven track record of developing scalable security systems.
  • Strong background in data loss prevention and vulnerability management.
Stackforce AI infers this person is a Cloud Security and Threat Detection expert in the SaaS industry.

Contact

Skills

Core Skills

Cloud SecurityThreat DetectionData Loss PreventionRisk AssessmentData ExfiltrationVulnerability ManagementSecurity OperationsNetwork SecuritySystem Administration

Other Skills

SplunkTaniumGCPCisco ISEMcAfee ESMSecurity ResearchLinux AdministrationWindows AdministrationDigital ForensicsTerraformAWS Identity and Access Management (AWS IAM)Linux System AdministrationElastic Stack (ELK)ElasticsearchTechnical Support

About

I drive enterprise threat detection and cloud security strategy by turning fragmented telemetry and ad-hoc detections into scalable, repeatable systems. I shape how security decisions scale consistently across the organization.

Experience

8 yrs 11 mos
Total Experience
1 yr 4 mos
Average Tenure
10 mos
Current Experience

Take-two interactive

Lead Detection Engineer

Jul 2025Present · 10 mos · United States · Remote

  • Driving enterprise threat detection and cloud security strategy across Take-Two Interactive, including labels 2K, Zynga, Rockstar Games, and Ghost Story Games.
Cloud SecurityThreat DetectionSecurity Operations

Ripple

Sr. Threat Detection Engineer - Threat Detection

Jul 2022Apr 2025 · 2 yrs 9 mos · Dallas, Texas, United States · Remote

Robinhood

Security Engineer - Insider Trust

Apr 2022Jul 2022 · 3 mos · Dallas-Fort Worth Metroplex · Remote

  • Enhanced data loss prevention by developing custom threat detections in Splunk, supported by metrics to track and demonstrate success in reducing exfiltration efforts.
  • Optimized Splunk's capacity for security log analysis by increasing data ingestion by 36%, enabling improved threat detection and response.
  • Provided strategic guidance to senior management on insider threats and emerging security trends, contributing to proactive risk mitigation and enhanced security posture.
  • Conducted in-depth technical security assessments of Splunk and Code42, identifying vulnerabilities and compliance gaps. Developed and presented actionable mitigation strategies to address identified
  • risks.
SplunkData Loss PreventionThreat Detection

Procore technologies

Sr. Security Engineer

Jun 2021Mar 2022 · 9 mos

Citi

Security Engineer - Insider Threat

Nov 2020Jun 2021 · 7 mos · Irving, Texas, United States

  • Created a risk assessment Splunk dashboard, which correlated email and data loss prevention data. This dashboard baselined user’s behavior, utilizing user behavior analytics with the goal to identify abnormal behavior.
  • Created a playbook and Splunk dashboard that identified data exfiltration policy violations. The process allowed the team to quickly identify and investigate users.
  • Utilized DTEX and Proofpoint logs to create a Splunk dashboard that identified users that were exfiltrating compressed files through email.
SplunkRisk AssessmentData Exfiltration

Booz allen hamilton

Sr. Security Consultant

Mar 2019Nov 2020 · 1 yr 8 mos · Dallas, TX, United States

  • Provided engineering support building a Cyber Fusion Center by implementing Tanium FIM, Nexpose, and Splunk within AWS GovCloud.
  • Implemented Geo-Blocking as a Service, this service ran on GCP utilizing Kubernetes, Stackdriver, Gardener, and Maxmind. After implementing this service, I integrated the logs from Stackdriver & StackRox into Splunk, where I then created security use cases for alerting within the AWS & GCP environments.
  • Created dashboards, and reports that provide metrics on vulnerability scanning coverage, vulnerabilities identified within the client's environment, and remediation SLA compliance by business unit. This allowed business units to access their data on-demand and facilitates drill down to the underlying data while providing roll-up capabilities for executive reporting.
  • Performed assessment of the client's current Nexpose scanning capability and identify areas of opportunity and learning that would assist with Nessus implementation.
  • Performed analysis to identify the complexity of implementing a centralized ticketing system for business units to use for vulnerability management. The ticketing system was used to track vulnerability identification, assignment, and remediation.
  • Created an automation script for the vulnerability advisory services team utilizing python. This script decreased a 6-hour process to a 15-minute process, as well as decreased the number of people needed to complete this process.
TaniumSplunkVulnerability ManagementSecurity Operations

Optiv inc

Threat Analyst

Aug 2018Mar 2019 · 7 mos · Dallas-Fort Worth Metroplex

Cisco

Security Solutions Engineer

May 2018Aug 2018 · 3 mos · Dallas-Fort Worth Metroplex

  • Administered and provided engineering support with Cisco ISE to monitor network traffic
  • Assisted in analyzing potential security events detected in network environments and either resolve or escalate the event as appropriate
  • Deployed ISE in wired environment to perform Dot1x port-based authentication configure the posture polices perform Change Of Authorization CoA for users connecting to the corporate network
Cisco ISENetwork Security

Mcafee

Security Operations Analyst

Oct 2017Feb 2018 · 4 mos · Plano, Texas

  • Utilized McAfee ESM to proactively monitor, identify and analyze complex internal and
  • external threats, including viruses, targeted attacks, and unauthorized access, and mitigate risk to IT systems Conduct security research to maintain current knowledge of latest security trends and issues
  • Utilized McAfee ePO to perform investigations of network and hosts/endpoints for malicious activity, to include analysis of packet captures, and assist in efforts to detect, confirm, contain, remediate, and recover from attacks.detection systems, web application, firewalls, messaging security platforms, vulnerability scanners etc.
McAfee ESMSecurity ResearchSecurity Operations

Baylor scott & white health

Security Associate

Aug 2017Oct 2017 · 2 mos · Dallas, Texas

  • Identified malicious and anomalous activity based on event data from firewalls, WAF, IPS,
  • and other sources utilizing Splunk, Red Line, and Proof point
  • Performed digital forensics/malware analysis on infected PC’s/laptops
  • Monitored SIEM and logging environments with Splunk for security events and alerts to threats, intrusions, and/or compromise
  • Coordinate escalations to internal support teams to ensure timely delivery of incident resolutions Perform network/system/application/log intrusion detection analysis and trending

Teksystems

2 roles

Network /Linux Administrator (100% Remote)

May 2017Jan 2018 · 8 mos

  • Administrate roughly 600 -800 Red Hat 6 and Windows servers
  • Install new/rebuild existing servers and configure software, services, directories, storage, etc. in accordance with standards and project/operational requirements
  • Performed daily system monitoring, verifying the integrity and availability of all hardware, server resources, systems and key processes, reviewing system and application logs, and verifying completion of scheduled jobs such as backups
  • Perform ongoing performance tuning, hardware upgrades, and resource optimization as required. Configure CPU, memory, and disk partitions as required
Linux AdministrationWindows AdministrationSystem Administration

NOC and ATC Analyst

Mar 2016Apr 2017 · 1 yr 1 mo

  • Serve as a liaison between various support groups during system outages, managing high level bridges and working with third party vendors to remediate nationwide outages affecting millions of customers.
  • Tier 1 support for Red Hat and Windows Operating systems.
  • Responsible for the monitoring, surveillance and resolution of all incidents.
  • Respond to internal telephone calls for technical support in a timely manner and explain technical situations to non-technical individuals.
  • Perform basic systems testing and operational tasks (installation of patches, network connectivity testing, and software updates.
  • Report trends in hardware and application performance to assist senior technical personnel to predict future issues or outages.

Celanese

Information Security Analyst - Intern

May 2017Aug 2017 · 3 mos · Irving, Texas

  • Analyzed sensitive authentication activities and privilege combinations that could lead to
  • abuse; monitored privileged access activity for possible abuse; monitor suspicious and/ or inappropriate web activity; assessed data leakage vulnerabilities; and establish baseline usage information and trends
  • Researched and applied public threat intelligence to enhance the analytic model and security of the company
  • Developed a Python script that automated application logs that was integrated within the Splunk enviroment.
  • Supported the company by conducting vulnerability/security assessments including security control validation, network, and web application penetration testing, and reporting by utilizing Kali Linux operating system and various security tool
  • Performed a penetration test within the printer network, resulting in 55+ printers being compromised, which included a report on remediation and how the systems were compromised
SplunkDigital ForensicsSecurity Operations

Education

University of North Texas

Bachelor of Science (BS) — Integrative Studies

Jan 2017Jan 2018

Tarrant County College

Associate of Applied Science (A.A.S.) — Computer and Information Systems Security/Information Assurance

Jan 2016Jan 2017

Stackforce found 100+ more professionals with Cloud Security & Threat Detection

Explore similar profiles based on matching skills and experience